Well it depends on how your servlet interacts with your database. First of all, beware of designing it in a way which can leave you open to SQL-injection. Second, consider implementing some sort of...